|
http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=3966 [º¹»ç]
´ÙÀ½ ÄÚµå´Â autodigÀÇ ¼Ò½ºÀÌ´Ù.
#include <stdio.h>
#include <stdlib.h>
#include <unistd.h>
int main(int argc, char **argv){
char cmd[100];
if( argc!=2 ){
printf( "Auto Digger Version 0.9\n" );
printf( "Usage : %s host\n", argv[0] );
exit(0);
}
strcpy( cmd, "dig @" );
strcat( cmd, argv[1] );
strcat( cmd, " version.bind chaos txt");
system( cmd );
}
À̸¦ ÀÌ¿ëÇÏ¿© level4ÀÇ ±ÇÇÑÀ» ¾ò¾î¶ó.
more hints.
- µ¿½Ã¿¡ ¿©·¯ ¸í·É¾î¸¦ »ç¿ëÇÏ·Á¸é?
- ¹®ÀÚ¿ ÇüÅ·Π¸í·É¾î¸¦ Àü´ÞÇÏ·Á¸é?
ÀÌ ÈùÆ®¸¦ º¸°í Æä½º¿öµå¸¦ ¾ò¾î³»´Â ¹®Á¦¿´´Âµ¥¿ä.
¸¸¾à ¿¹·Î autodig "/bin/bash"¶ó°í ÀÔ·ÂÇØ¼ ½ÇÇàÇÏ°Ô µÇ¸é
"dig @/bin/bash version.bind chaos txt"¶ó´Â ¹®ÀÚ¿ÀÌ cmd·Î ÀÔ·ÂµÇ°Ô µÉÅĵ¥
Ç®À̵éÀ» º¸´Ï±î ¸î¸î ºÐµéÀº "/bin/bash;my-pass"¶ó´Â ¹æ¹ýÀ¸·Î Ǫ¼Ì´õ¶ó°í¿ä... (Àú´Â "|my-pass"¶ó°í Ç®¾ú´Âµ¥ ¸»ÀÔ´Ï´Ù.)
±×·±µ¥ ÀÌ·¸°Ô µÇ¸é dig¸í·É¾îÀÇ ¿É¼ÇÀ¸·Î @/bin/bash¶ó´Â °ªÀÌ µé¾î°¡´Â°Ô ¾Æ´Ñ°¡¿ä?
±×·¯´Ï±î ¾ÕÀÇ dig¸í·É¾î¿Í ±¸ºÐ½ÃÄÑÁÖ±â À§Çؼ "|/bin/bash"³ª ";/bin/bash"°°Àº Çü½ÄÀ¸·Î ¸í··¾î°¡ µé¾î°¡¾ß µÇ´Â°Ô ¾Æ´Ñ°¡¿ä?
¿Ö ±¸ºÐ ¾øÀÌ ¹Ù·Î /bin/bash¶ó°í ÀÔ·ÂÇØµµ µÇ´Â°ÇÁö ±Ã±ÝÇÕ´Ï´Ù. |
Hit : 3629 Date : 2011/05/01 10:00
|